Skip to content
COOEY

EXPOSURES › CVE-2021-30116

CVE-2021-30116

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-30116 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

Kaseya VSA exposed session IDs, enabling attackers to compromise systems and potentially deploy ransomware.

A vulnerability in Kaseya VSA allowed attackers to obtain session IDs, facilitating further attacks and potentially ransomware deployment. DIB organizations using VSA face significant exposure and compliance risks (CMMC DF, MP) and must immediately patch and review access controls. This incident highlights the importance of vendor risk management and timely patching.

Shame score — The exposure of session IDs enabled unauthorized access and potential ransomware deployment, demonstrating a significant security oversight by Kaseya.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.

SENTIMENT · TRUSTED SOURCES
synthesis negative -0.50
Vulnerability confirmed but no major fallout reported in this source
cooey ↗ negative -0.50
Neutral technical assessment
"Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.